2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-33655 | MEDIUM | 6.7 | 0.3% | Jul 18, 2022 | When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds. |
| CVE-2021-46784 | MEDIUM | 6.5 | 3.6% | Jul 17, 2022 | In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Servic... |
| CVE-2021-40149 | MEDIUM | 5.9 | 6.0% | Jul 17, 2022 | The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory. ... |
| CVE-2021-4135 | MEDIUM | 5.5 | 0.2% | Jul 14, 2022 | A memory leak vulnerability was found in the Linux kernel's eBPF for the Simulated networking device driver in the way u... |
| CVE-2021-26382 | MEDIUM | 4.4 | 0.2% | Jul 14, 2022 | An attacker with root account privileges can load any legitimately signed firmware image into the Audio Co-Processor (AC... |
| CVE-2021-39028 | MEDIUM | 5.4 | 0.4% | Jul 14, 2022 | IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to HTTP header i... |
| CVE-2021-39019 | MEDIUM | 6.5 | 0.7% | Jul 14, 2022 | IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose highly sensitiv... |
| CVE-2021-39018 | MEDIUM | 4.3 | 0.5% | Jul 14, 2022 | IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose sensitive infor... |
| CVE-2021-39017 | MEDIUM | 6.5 | 0.8% | Jul 14, 2022 | IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker ... |
| CVE-2021-39016 | MEDIUM | 4.3 | 0.5% | Jul 14, 2022 | IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 does not sufficiently monitor ... |
| CVE-2021-39015 | MEDIUM | 5.4 | 0.4% | Jul 14, 2022 | IBM Engineering Lifecycle Optimization - Publishing 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vu... |
| CVE-2021-46827 | MEDIUM | 6.1 | 0.4% | Jul 13, 2022 | An issue was discovered in Oxygen XML WebHelp before 22.1 build 2021082006 and 23.x before 23.1 build 2021090310. An XSS... |
| CVE-2021-39041 | MEDIUM | 5.3 | 0.9% | Jul 12, 2022 | IBM QRadar SIEM 7.3, 7.4, and 7.5 may be vulnerable to partial denial of service attack, resulting in some protocols not... |
| CVE-2021-40016 | MEDIUM | 6.5 | 0.3% | Jul 12, 2022 | Improper permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability will aff... |
| CVE-2021-40013 | MEDIUM | 6.5 | 0.2% | Jul 12, 2022 | Improper permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability will aff... |
| CVE-2021-41042 | MEDIUM | 5.3 | 0.9% | Jul 7, 2022 | In Eclipse Lyo versions 1.0.0 to 4.1.0, a TransformerFactory is initialized with the defaults that do not restrict DTD l... |
| CVE-2021-44791 | MEDIUM | 6.1 | 1.9% | Jul 7, 2022 | In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back i... |
| CVE-2021-3696 | MEDIUM | 4.5 | 0.4% | Jul 6, 2022 | A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data cor... |
| CVE-2021-3695 | MEDIUM | 4.5 | 0.4% | Jul 6, 2022 | A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage ... |
| CVE-2021-37839 | MEDIUM | 4.3 | 1.1% | Jul 6, 2022 | Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have... |
| CVE-2021-31679 | MEDIUM | 6.5 | 0.5% | Jul 6, 2022 | An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that allows attackers to delete admin and other ... |
| CVE-2021-31678 | MEDIUM | 6.5 | 0.5% | Jul 6, 2022 | An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that can delete import information about a user'... |
| CVE-2021-31677 | MEDIUM | 6.5 | 0.5% | Jul 6, 2022 | An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that can modify admin and other members' passwor... |
| CVE-2021-31676 | MEDIUM | 6.1 | 0.7% | Jul 6, 2022 | A reflected XSS was discovered in PESCMS-V2.3.3. When combined with CSRF in the same file, they can cause bigger destruc... |
| CVE-2021-46687 | MEDIUM | 4.9 | 0.7% | Jul 6, 2022 | JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Admi... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now